关联漏洞
标题:Microsoft Windows Uniscribe 缓冲区错误漏洞 (CVE-2017-0089)Description:Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。Uniscribe(又名Unicode Script Processor)是其中的一个能够使Windows操作系统正确演示Unicode文字的组件。 Microsoft Windows中的Uniscribe存在远程代码执行漏洞。远程攻击者可借助特制的Web站点利用该漏洞执行任意代码。以下版本受到影响:Microsoft Windows Vista SP2,Windows Server 2008 SP2和R2 SP1
Description
CVE-2017-0089 Learn more at National Vulnerability Database (NVD) • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
介绍
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0089
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0083, CVE-2017-0084, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, and CVE-2017-0090.
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
BID:96606
URL:http://www.securityfocus.com/bid/96606
CONFIRM:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0089
EXPLOIT-DB:41652
URL:https://www.exploit-db.com/exploits/41652/
SECTRACK:1037992
URL:http://www.securitytracker.com/id/1037992
Microsoft Corporation
文件快照
[4.0K] /data/pocs/5c8923d7982aa0d68e6a96c8cf01b6a24d5978f1
└── [ 889] README.md
0 directories, 1 file
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮件到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对 POC 代码进行快照,为了长期维护,请考虑为本地 POC 付费/捐赠,感谢您的支持。